P
P
Pamir2017-02-13 20:00:53
Law in IT
Pamir, 2017-02-13 20:00:53

Can I deploy an application to Azure if I am required to provide First Name, Last Name, and Email during registration?

Good evening. We are developing a web application, for which you need to fill in 3 fields:
First name, Last name, email address.
Question:
1. Is it necessary to request permission to process personal data, if the Surname and Name are shown to other users, the Email will be used only for user authorization?
2. Can this data be stored in Azure?
Thank you!

Answer the question

In order to leave comments, you need to log in

4 answer(s)
S
Saboteur, 2017-02-13
@saboteur_kiev

Of course they are.
But you should clarify not this, but what to do with them, because different combinations of personal data require a different attitude, up to the requirement to store them within the Russian Federation.
For example, if a phone number is added to the name / surname / email, and the company's policy regarding the processing of personal data has not been published (namely, the procedure for the user's consent to the fact that his data is collected and processed has not been established) - a fine.
You better consult with a lawyer, or read the primary sources, or check with Roskomnadzor.

I
Ivan Bogachev, 2017-02-13
@sfi0zy

UPD: Comments began to pour in that I was joking and trolling.

So yes. You're kidding. FZ-152, article 3 paragraph 1:
My name, surname and postal address definitely refer directly or indirectly to me. As Saboteur
rightly noted , the only question is what to do with them, and it is better to consult a lawyer with this issue.

N
Nwton, 2017-02-13
@Nwton

There is a Privacy policy which says:
We do not collect, process, and in any other way do not use users' personal data (email and full name) unless you send a letter to our email (in this case it is stored on our server). We do not sell or rent to any third party any personal information we collect from you, nor will we acquire or otherwise receive personal information from any third party.
We do not share your personal data (name and email address) with other companies and business partners. This data is stored in Microsoft Azure, where we store all of our data. We do not knowingly collect or store personal information from anyone under the age of 13. If the user is under 13 years old, we do not recommend registering in our application and sending us personal information. If we become aware of the registration of a user under the age of 13, we will immediately delete all information about him.

1) You collect data. Already a lie in the first sentence
2) "We do not transfer data to third parties" contains absolutely any third parties and it makes no sense to repeat 10 times that you do not sell, do not transfer, neither to business partners, nor to anyone
3) Where are 13 years from? In the right there is a trace. groups: 0-6, 6-14, 14-18
Suggestion:
1) google "how to write a user agreement" and read some instructions
2) google "user agreement" and read some agreements from other projects

E
Eugene, 2017-02-15
@hokop

If you look at the law:
1. You process personal data.
2. Storage in terms of 152-FZ is also processing:
3. Based on the fact that storage is processing, you transfer PD to third parties (Azure).
4. But since:
You can't use Azure.
Otherwise, your service is threatened with blocking on the territory of the Russian Federation.
This is if the law.
If according to the current situation, then at least be sure to publish a policy regarding the processing of personal data, check the box that the data is processed with consent. The risk that you are for Azure, and the processing of only "First Name, Last Name and Email" will be minimal.
PS
Since July 1, fines for violation of 152-FZ have been increased. In particular, the absence of the Policy on the site is now up to 30k. (See the new wording of Article 13.11 of the Code of Administrative Offenses)

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question